- Home
- /
- Categories
- /
- Security
Security
Security scanning and vulnerability detection
compliance-frameworks
by Hack23
Multi-framework compliance (ISO 27001, NIST CSF, CIS Controls, GDPR, NIS2, EU CRA, SOC 2), control mapping
code-review
by mishankov
Perform comprehensive software code reviews focused on correctness, regressions, security, reliability, performance, and test quality. Use when asked to review pull requests, commits, branches, patches, or source files and deliver prioritized findings with severity, concrete impact, and file/line references.
code-audit
by pietz
Structural health assessment for codebases. Use when the user asks to audit code quality, assess code health, review a codebase, find technical debt, clean up code structure, or identify refactoring opportunities. Also use when asked to do a "code audit", "codebase review", "quality assessment", or "tech debt analysis". Provides parallel multi-lens analysis via sub-agents with specialized checklists for code health, cross-module coherence, refactoring detection, and security.
code-review-checklist
by htooayelwinict
Review code changes for correctness, security, performance, and maintainability. Use for PR reviews, code audits, pre-merge checks, or quality validation of Laravel + React + Python code. EXCLUSIVE to reviewer agent.
agoragentic-buzz-signed-workspace-evidence
by rhein1
Convert exported Block Buzz / Nostr workspace events into bounded Agoragentic evidence. Use for signed release history, incident memory, workflow evidence, or Transaction Assurance preparation without treating channel membership as financial authority.
Quality Engineer Agent
by gajakannan
Opinionated AI‑agent development framework with a reference Insurance CRM implementation.
securing-ai-generated-code
by chrbailey
Reviews AI-generated code for security vulnerabilities before commit. Checks for injection flaws, privilege escalation, hardcoded secrets, insecure defaults, and missing input validation. Use when reviewing code written by AI coding agents, after code generation, or before committing AI-assisted changes.
writing-meeting-notes
by danbars
Use when a meeting just occurred and notes need to be turned into a clear summary with decisions, action items, owners, and dates.
Solaudit - Smart Contract Security Scanner
by NguyenMinhGitHub
Solidity smart contract security auditor. Detect reentrancy, overflow, access control issues. 50+ vulnerability patterns. CI/CD ready. Free CLI tool.
information-security-manager-iso27001
by nimeshgurung
Senior Information Security Manager specializing in ISO 27001 and ISO 27002 implementation for HealthTech and MedTech companies. Provides ISMS implementation, cybersecurity risk assessment, security controls management, and compliance oversight. Use for ISMS design, security risk assessments, control implementation, and ISO 27001 certification activities.
AWS Penetration Testing
by jcastillotx
This skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation", or needs guidance on Amazon Web Services security assessment.
security-by-design
by Hack23
Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC
security-scan
by IHKREDDY
Run security checks before PR including secrets, vulnerabilities, and best practices
supabase-postgres-best-practices
by kunhai-88
"Supabase 出品的 Postgres 性能优化与最佳实践。在编写、评审或优化 Postgres 查询、表结构设计或数据库配置时使用。"
asking-questions
by arielperez82
Guidance for asking clarifying questions when user requests are ambiguous, have multiple valid approaches, or require critical decisions. Use when implementation choices exist that could significantly affect outcomes.
Elixir Code Review Skill
by vircung
Use this skill to ensure Elixir code meets BEAM VM best practices, security standards, and performance requirements while maintaining the functional programming paradigms that make Elixir powerful.
elm-security-review
by bromanko
This skill should be used when the user asks for "security review", "vulnerability scan", "audit Elm security", "security audit", "find vulnerabilities", "check for security issues", or wants a deep security analysis of Elm code including port safety, JSON decoder validation, and XSS prevention.
angular-enterprise-review
by JoseGusnay
"Professional Code Auditor for Angular Enterprise Architecture. Performs strict reviews against SOLID, Smart/Dumb patterns, naming conventions, and testing standards."
rails-security
by scottwater
"Run a multi-agent security review of Rails application code. Use when the user asks for a Rails security review or audit, or raises a specific concern — authorization/IDOR/tenant isolation, XSS/SQL injection/SSRF, vulnerable gems/Brakeman/bundle audit, or prompt injection in AI features."
Burp Suite Web Application Testing
by automindtechnologie-jpg
This skill should be used when the user asks to "intercept HTTP traffic", "modify web requests", "use Burp Suite for testing", "perform web vulnerability scanning", "test with Burp Repeater", "analyze HTTP history", or "configure proxy for web testing". It provides comprehensive guidance for using Burp Suite's core features for web application security testing.
blind-spot-scanner
by qingchunwuhui
全景盲点扫描仪 - 使用 5W1H 方法强制拷问文档/方案,发现逻辑漏洞和执行盲点。
grounded-research
by Out-treatyofversailles910
Enforces source-grounded, citation-first research discipline. Use this skill whenever the user asks to research a topic, fact-check a claim, summarize recent findings, look up current information, explain what the evidence says about something, or produce any factual output where accuracy and verifiability matter. Trigger even on conversational phrasing like "what's the deal with X", "is it true that Y", "what do experts say about Z", or "can you check if..." — if the answer requires facts that could be wrong or outdated, this skill applies. When in doubt, use it.
workers-specialist
by SteveLeve
Provide Cloudflare Workers runtime guidance for routing, bindings, performance, security headers, rate limiting, and Hono patterns used in this repo.
spring-boot-ultimate
by halilugur
Spring Boot patterns, best practices, and code generation for REST APIs, JWT authentication, JPA, pagination, and modern Spring Boot development (Java 21+, Spring Boot 4.x)